10 free, exam-style Certified Cloud Security Professional (CCSP) (CCSP) practice questions with answers and
explanations. No signup required. Work through them below, then take the
full free CCSP practice test to study every exam domain.
These 10 free CCSP questions are organized by exam domain, so you can see how each part of the Certified Cloud Security Professional (CCSP) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Cloud Concepts, Architecture and Design
Question 1
Which data sanitization method is MOST effective in a multi-tenant cloud storage environment where the customer does not have physical access to the storage media?
- Physical destruction of storage media
- Overwriting data with random patterns
- Cryptographic erasure (crypto-shredding)
- Degaussing the storage drives
Show answer & explanation
Correct answer: C - Cryptographic erasure (crypto-shredding)
Question 2
An attacker exploits timing differences in CPU cache access to extract cryptographic keys from a co-located virtual machine. This is known as:
- VM escape
- Container breakout
- Side-channel attack
- Brute-force attack
Show answer & explanation
Correct answer: C - Side-channel attack
Domain 2: Cloud Data Security
Question 3
What is the PRIMARY difference between tokenization and encryption?
- Tokenization preserves data format while encryption changes the data structure and length
- Tokens have no mathematical relationship to the original data, while encrypted data can be decrypted with the correct key
- Encryption requires distributing keys to all systems while tokenization centralizes sensitive data
- Tokenization provides stronger protection against brute-force attacks than symmetric encryption
Show answer & explanation
Correct answer: B - Tokens have no mathematical relationship to the original data, while encrypted data can be decrypted with the correct key
Question 4
An organization receives a legal hold notice while simultaneously processing a GDPR data deletion request from the same individual. How should this conflict be resolved?
- Delete the data immediately to comply with the GDPR erasure request in full
- Preserve the data under legal hold, document the justification, and delete non-held data
- Suspend all processing of the data until both obligations have been formally reconciled
- Notify the supervisory authority and request guidance on which obligation takes priority
Show answer & explanation
Correct answer: B - Preserve the data under legal hold, document the justification, and delete non-held data
Domain 3: Cloud Platform and Infrastructure Security
Question 5
A cloud architect is asked to design for 99.99% availability. This allows approximately how much downtime per year?
- 87.6 hours (about 3.65 days)
- 8.76 hours
- 52.56 minutes
- 5.26 minutes
Show answer & explanation
Correct answer: C - 52.56 minutes
Question 6
An organization's critical application requires a maximum of 15 minutes of data loss and 1 hour to restore service. These requirements define:
- RPO = 1 hour, RTO = 15 minutes
- RPO = 15 minutes, RTO = 1 hour
- RPO = 15 minutes, RTO = 15 minutes
- RPO = 1 hour, RTO = 1 hour
Show answer & explanation
Correct answer: B - RPO = 15 minutes, RTO = 1 hour
Domain 4: Cloud Application Security
Question 7
An attacker exploits a vulnerability to gain administrator access to a cloud application from a regular user account. This is an example of which STRIDE category?
- Spoofing of identity
- Repudiation of actions
- Information Disclosure
- Elevation of Privilege
Show answer & explanation
Correct answer: D - Elevation of Privilege
Question 8
A Cloud Access Security Broker (CASB) provides which FOUR pillars of functionality?
- Authentication, Authorization, Accounting, Auditing
- Visibility, Compliance, Data Security, Threat Protection
- Encryption, Hashing, Tokenization, Masking
- Network, Compute, Storage, Management
Show answer & explanation
Correct answer: B - Visibility, Compliance, Data Security, Threat Protection
Domain 5: Cloud Security Operations
Question 9
The KEY distinction between incident management and problem management is:
- Incident management identifies root causes and problem management restores service
- Incident management restores service and problem management eliminates root causes
- Incident management is reactive while problem management is exclusively proactive
- Problem management handles individual disruptions and incident management addresses patterns
Show answer & explanation
Correct answer: B - Incident management restores service and problem management eliminates root causes
Question 10
A SIEM system correlates a failed login attempt from an unusual geographic location with a subsequent successful login and large data download. This correlation suggests:
- A legitimate user accessing data remotely through a VPN during authorized travel
- A potential account compromise with credential theft requiring immediate investigation
- An automated service account performing a scheduled data synchronization job
- A brute-force attack that was partially blocked by the account lockout policy
Show answer & explanation
Correct answer: B - A potential account compromise with credential theft requiring immediate investigation
The rest of the CCSP blueprint
The CCSP exam also covers these domains. Drill them in the full free practice test:
- Domain 6: Legal, Risk and Compliance